⚠️

Action Required: Terms of Service Update Effective June 1, 2025

We've updated our Terms of Service to reflect new data processing standards and AI-powered infrastructure features. Please review the changes by June 1, 2025 to maintain uninterrupted service access.

Showing 12 updates
May 2025
Breaking Terms
ToS v4.2

Terms of Service — Major Revision

Comprehensive update to our Terms of Service covering AI-powered infrastructure management, revised data processing obligations, updated liability provisions, and new acceptable use policy for automated workloads.

Key Changes
Added Section 12: AI-Assisted Resource Management — covers automated scaling decisions and AI optimization features
Revised Section 7.3: Data Processing — expanded definitions to include cross-border data transfers and third-party subprocessors
Updated Section 4.1: Service Credits — modified SLA credit calculation for multi-region deployments
New Section 15: Acceptable Use Policy — explicit guidelines for GPU compute, crypto mining restrictions, and automated workloads
Removed legacy Section 9: Email Hosting Provisions — consolidated into general hosting terms

Full Change Log

Section 12 — AI-Assisted Resource Management: CloudNexus may deploy AI-driven algorithms to optimize resource allocation across your infrastructure. These include automated vertical and horizontal scaling decisions, predictive load balancing, and intelligent caching strategies. You retain full override capability through the management console and API. AI recommendations do not constitute service commitments and may be adjusted based on system health metrics.

Section 7.3 — Data Processing Updates: Expanded our data processing framework to comply with evolving international regulations including EU AI Act provisions, China PIPL cross-border transfer mechanisms, and California's updated data privacy requirements. All subprocessors are now listed in Appendix C of the full document.

Section 15 — Acceptable Use Policy: Explicitly prohibits cryptocurrency mining on shared and VPS infrastructure. GPU instances may be used for ML training and rendering workloads only. Automated scraping of third-party services without explicit authorization is prohibited. Excessive network I/O patterns triggering abuse detection may result in temporary suspension pending review.

Privacy
PP v3.8

Privacy Policy — Telemetry & Analytics Update

Updated our data collection disclosures to include infrastructure telemetry, performance analytics, and security monitoring data. Added opt-out mechanisms for non-essential analytics collection.

Key Changes
Added Section 4.2: Infrastructure Telemetry — disk I/O metrics, network throughput, and CPU performance data collected for service optimization
Added Section 6.1: Opt-Out Procedures — customers may disable non-essential analytics via the dashboard under Settings > Privacy Controls
Updated Section 2.1: Data Retention — clarified 90-day retention for access logs and 12-month retention for security event data
April 2025
Security
Sec v2.1

Security Standards — SOC 2 Type II Recertification

CloudNexus has achieved SOC 2 Type II recertification for the 2025 audit period. Updated security documentation reflects enhanced access controls, encryption-at-rest mandates for all storage tiers, and new incident response SLAs.

Key Changes
AES-256 encryption now mandatory for all storage tiers including cold storage (previously optional for cold tier)
New incident response SLA: P1 security events acknowledged within 15 minutes, initial mitigation within 2 hours
Enhanced IAM requirements: mandatory 2FA for all administrative console access
Quarterly penetration testing now conducted by two independent third-party firms
Security
DDoS v1.4

DDoS Protection — Policy Enhancement

Enhanced DDoS mitigation policies now include application-layer (Layer 7) attack protection for all Professional and Enterprise tier customers. Updated abuse response procedures and clarified mitigation response times.

Key Changes
Layer 7 DDoS protection included at no additional cost for Professional+ plans
Mitigation response time reduced from 5 minutes to under 60 seconds for volumetric attacks
New automated attack pattern learning system reduces false positive rate by 85%
March 2025
Terms
SLA v3.0

Service Level Agreement — Availability & Performance

Revised SLA commitments with improved availability guarantees and new performance benchmarks for database replication latency, object storage durability, and CDN hit rates.

Key Changes
Infrastructure uptime SLA increased from 99.99% to 99.999% for Professional and Enterprise tiers
New performance SLAs: database replication lag <100ms, object storage durability 99.999999999%
Service credit calculation simplified — credits auto-issued to account balance within 48 hours of SLA miss
Maintenance window definitions updated — emergency maintenance excluded from downtime calculations
Privacy
DR v1.2

Data Residency — New Regional Compliance Options

Expanded data residency guarantees to support regional data sovereignty requirements. Customers can now pin their data to specific geographic regions with contractual guarantees against cross-border transfer.

Key Changes
Data residency pinning available for EU, US, APAC, and LATAM regions
Contractual addendum available for strict data sovereignty requirements (GDPR, China PIPL, Brazil LGPD)
Added audit trail for all cross-region data movement events
February 2025
Breaking Feature
API v1 → v2

API v1 Deprecation — Migration to API v2

API v1 will be sunset on September 1, 2025. All customers using API v1 endpoints must migrate to API v2. API v2 includes breaking changes to authentication, resource identifiers, and pagination models.

Breaking Changes
API v1 endpoints (/v1/*) will return 410 Gone after September 1, 2025
Authentication migrated from API key header to OAuth 2.0 / mTLS
Resource IDs now use UUID v7 format instead of integer-based IDs
Pagination uses cursor-based model replacing offset/limit parameters
New rate limiting model with per-endpoint limits and burst capacity
January 2025
Privacy
GDPR v2.0

GDPR & CCPA — Enhanced Data Subject Rights

Enhanced data subject rights management tools including automated data export, right to erasure workflows, and updated Data Processing Agreements (DPA) aligned with EU Standard Contractual Clauses 2021.

Key Changes
Automated GDPR data export: complete data package delivered within 24 hours via the compliance portal
Right to erasure workflow with 30-day completion guarantee and verification report
DPA updated to incorporate EU Standard Contractual Clauses (2021/914)
CCPA/CPRA: automated opt-out signal detection for global privacy controls
Privacy
SP v1.6

Subprocessor Registry — Quarterly Update

Quarterly update to our registered subprocessors. Added 3 new subprocessors for AI/ML services and removed 1 vendor whose contract has expired.

Changes
Added: AWS — AI/ML model inference (US-East, EU-West regions)
Added: Fastly — CDN edge delivery (global)
Added: Datadog — infrastructure monitoring and alerting (US, EU)
Removed: New Relic — monitoring services (contract expired, migrated to Datadog)
December 2024
Terms
BP v2.3

Billing & Payment — Pro-Proration & Invoicing

Updated billing policies to include hourly pro-ration for all compute resources, improved invoice granularity, and new payment method support including SEPA and wire transfer for Enterprise accounts.

Key Changes
All compute resources now billed hourly with daily invoicing (previously monthly for Starter tier)
Enhanced invoice breakdown: per-resource cost allocation with tag-based grouping
New payment methods: SEPA Direct Debit, wire transfer, and purchase orders for Enterprise
Overage notification thresholds updated: alerts at 75%, 90%, and 100% of monthly budget
November 2024
Security
IR v1.3

Incident Response — Updated Communication Protocol

Revised our incident response communication policy to provide more frequent status updates during active incidents and post-incident reports within 5 business days of resolution.

Key Changes
Status page updates every 30 minutes during active P1/P2 incidents (previously 60 minutes)
Post-incident reports now include root cause analysis, timeline, and preventive measures
Dedicated incident email notification for Enterprise customers with custom escalation paths
Revised severity classifications with clearer definitions for service impact levels
Security Feature
BK v1.1

Backup & Disaster Recovery — Policy Enhancement

Enhanced backup policies now mandate geographically redundant backups for all managed databases and offer automated failover testing capabilities.

Key Changes
All managed databases automatically backed up to a geographically separate region
Automated failover testing available on a monthly schedule for Enterprise tier
Backup retention periods extended: daily backups retained for 30 days, weekly for 90 days

SLA & Performance Benchmark Changes

Comparison of key service commitments before and after the March 2025 SLA update.

d>
Metric Previous (SLA v2.8) Current (SLA v3.0) Status
Infrastructure Uptime 99.99% 99.999% ↑ Improved
DB Replication Lag Not specified < 100ms (p99) ✦ New
Object Storage Durability 99.99999999% 99.999999999% ↑ Improved
CDN Hit Rate Not specified > 95% (cached) ✦ New
Incident Response P1 30 min acknowledgment 15 min acknowledgment ↑ Improved
Service Credit Payout Next billing cycle Within 48 hours ↑ Improved
Legacy Email Hosting SLA 99.95% Discontinued ✕ Deprecated

🔔 Stay Updated

Subscribe to receive policy change notifications via email. We'll only send alerts for changes that affect your account.